Rockwell 1756 modules face DoS flaw
A CIP packet validation flaw in Rockwell Automation 1756-EN2, EN3, and ENBT communication modules can be exploited to disrupt device connections.
CISA has published an advisory for a denial-of-service vulnerability affecting Rockwell Automation's 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, used across critical manufacturing environments worldwide. The flaw, tracked as CVE-2026-9653, stems from improper validation of CIP Implicit Connection packets, allowing an attacker with network access to send crafted packets that continuously disrupt device connections. Connections recover automatically once the malicious traffic stops, limiting the impact to transient disruption rather than persistent outage.
Rockwell has released fixes for 1756-EN3 and 1756-EN2 (update to V12.002), while the 1756-ENBT module is discontinued and will not receive a patch. CISA notes no known public exploitation of this vulnerability at this time and recommends standard ICS network segmentation practices — isolating control system networks from business networks and the internet, and using VPNs for remote access. The vulnerability was responsibly reported by a researcher at Idaho National Laboratory.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free